Medium severity4.3NVD Advisory· Published Feb 28, 2023· Updated Apr 8, 2026
CVE-2023-1027
CVE-2023-1027
Description
The WP Meta SEO plugin for WordPress is vulnerable to unauthorized sitemap generation due to a missing capability check on the checkAllCategoryInSitemap function in versions up to, and including, 4.5.3. This makes it possible for authenticated attackers with subscriber-level access to obtain post categories. This vulnerability occurred as a result of the plugin relying on nonce checks as a means of access control, and that nonce being accessible to all authenticated users regardless of role.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2cpe:2.3:a:joomunited:wp_meta_seo:*:*:*:*:*:wordpress:*:*+ 1 more
- cpe:2.3:a:joomunited:wp_meta_seo:*:*:*:*:*:wordpress:*:*range: <=4.5.3
- (no CPE)range: <=4.5.3
Patches
Vulnerability mechanics
References
4- plugins.trac.wordpress.org/changeset/2870465/wp-meta-seo/trunknvdPatch
- plugins.trac.wordpress.org/changesetnvdPatch
- www.wordfence.com/threat-intel/vulnerabilities/id/4f589e21-7417-4b43-b580-4f1d3c2041f4nvdBroken Link
- www.wordfence.com/threat-intel/vulnerabilities/id/4f589e21-7417-4b43-b580-4f1d3c2041f4nvd
News mentions
0No linked articles in our index yet.